Application-level cybersecurity using multiple stages of classifiers
Abstract
Various embodiments include systems and methods to implement a security platform providing application-level cyberattack detection using multiple stages of classifiers. The security platform may use requests received by a web service to determine training data to train one or more machine learning models. The training data may be determined by instrumenting an application, such as a web service, with a first stage classifier to determine security events indicative of cyberattacks. The security platform may train machine learning models using aggregations of security events over various periods of time. The machine learning models may serve as second stage classifiers for the security platform.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
determining one or more access attempts of a compute resource, wherein a first stage classifier is associated with the compute resource; determining, based on the first stage classifier operating on the one or more access attempts, a security event indicative of a possible cyberattack on the compute resource, wherein the first stage classifier generates security events that indicates possible cyberattacks based on one or more of statistical analysis, textual analysis, or signature matching applied to individual access attempts; in response to the determination of the possible cyberattack by the first stage classifier:
determining, from among a plurality of second stage classifiers, a second stage classifier associated with a first period of time, wherein
the plurality of second stage classifiers comprise a classifier that operates on event data periods of five seconds or less and another classifier that operates on event periods of more than five seconds;
aggregating multiple security events in the first period of time into a security event dataset, wherein the security event is in the first period of time;
determining, based on the second stage classifier operating on the security event dataset associated with the first period of time, a cyberattack on the compute resource; and
blocking the cyberattack or one or more subsequent access attempts associated with the cyberattack based on the determination of the cyberattack by the second stage classifier.
2 . The method of claim 1 , further comprising:
determining, based on one or more characteristics of the cyberattack, security policy data.
3 . The method of claim 2 , further comprising:
providing the security policy data to the first stage classifier; and determining, by the first stage classifier using the security policy data, a subsequent cyberattack.
4 . The method of claim 1 , wherein the first stage classifier is instrumented within a service that receives the one or more access attempts.
5 . The method of claim 1 , wherein the first stage classifier has higher execution performance than the second stage classifier but a higher false positive rate than the second stage classifier.
6 . The method of claim 1 , wherein the plurality of second stage classifiers comprises a plurality of machine learning models trained on security event datasets associated with a plurality of periods of time.
7 . A system comprising:
a memory storing executable instructions; and one or more processors that execute the executable instructions to: determine one or more access attempts of a compute resource, wherein a first stage classifier is associated with the compute resource; determine, based on the first stage classifier operating on the one or more access attempts, a security event indicative of a possible cyberattack on the compute resource, wherein the first stage classifier generates security events that indicates possible cyberattacks based on one or more of statistical analysis, textual analysis, or signature matching applied to individual access attempts; in response to the determination of the possible cyberattack by the first stage classifier:
determine, from among a plurality of second stage classifiers, a second stage classifier associated with a first period of time, wherein
the plurality of second stage classifiers comprise a classifier that operates on event data periods of five seconds or less and another classifier that operates on event periods of more than five seconds;
aggregate multiple security events in the first period of time into a security event dataset, wherein the security event is in the first period of time;
determine, based on the second stage classifier operating on the security event dataset associated with the first period of time, a cyberattack on the compute resource; and
block the cyberattack or one or more subsequent access attempts associated with the cyberattack based on the determination of the cyberattack by the second stage classifier.
8 . The system of claim 7 , wherein the one or more processors further execute the executable instructions to:
determine, based on one or more characteristics of the cyberattack, security policy data.
9 . The system of claim 8 , wherein the one or more processors further execute the executable instructions to:
provide the security policy data to the first stage classifier; and determine, by the first stage classifier using the security policy data, a subsequent cyberattack.
10 . The system of claim 7 , wherein the first stage classifier is instrumented within a service that receives the one or more access attempts.
11 . The system of claim 7 , wherein the first stage classifier has higher execution performance than the second stage classifier but a higher false positive rate than the second stage classifier.
12 . The system of claim 7 , wherein the plurality of second stage classifiers comprises a plurality of machine learning models trained on security event datasets associated with a plurality of periods of time.
13 . One or more non-transitory computer-accessible storage media storing executable instructions that, when executed by one or more processors, cause a computer system to:
determine one or more access attempts of a compute resource, wherein a first stage classifier is associated with the compute resource; determine, based on the first stage classifier operating on the one or more access attempts, a security event indicative of a possible cyberattack on the compute resource, wherein the first stage classifier generates security events that indicates possible cyberattacks based on one or more of statistical analysis, textual analysis, or signature matching applied to individual access attempts; in response to the determination of the possible cyberattack by the first stage classifier:
determine, from among a plurality of second stage classifiers, a second stage classifier associated with a first period of time, wherein
the plurality of second stage classifiers comprise a classifier that operates on event data periods of five seconds or less and another classifier that operates on event periods of more than five seconds;
aggregate multiple security events in the first period of time into a security event dataset, wherein the security event is in the first period of time;
determine, based on the second stage classifier operating on the security event dataset associated with the first period of time, a cyberattack on the compute resource; and
block the cyberattack or one or more subsequent access attempts associated with the cyberattack based on the determination of the cyberattack by the second stage classifier.
14 . The non-transitory computer-accessible storage media of claim 13 , wherein the one or more processors further execute the executable instructions to:
determine, based on one or more characteristics of the cyberattack, security policy data.
15 . The non-transitory computer-accessible storage media of claim 13 , wherein the one or more processors further execute the executable instructions to:
provide the security policy data to the first stage classifier; and determine, by the first stage classifier using the security policy data, a subsequent cyberattack.
16 . The non-transitory computer-accessible storage media of claim 13 , wherein the first stage classifier is instrumented within a service that receives the one or more access attempts.
17 . The non-transitory computer-accessible storage media of claim 13 , wherein the plurality of second stage classifiers comprises a plurality of machine learning models trained on security event datasets associated with a plurality of periods of time.Join the waitlist — get patent alerts
Track US12463987B1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.